How a malicious help file can install a spyware keylogger

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Sophos said:
Do you think that Windows help file is safe? Think again.

Malware authors can create boobytrapped .HLP files, designed to infect your computer.

Take for instance, the strange .HLP file which was sent to SophosLabs by some of our customers at the end of August.

The file, Amministrazione.hlp ("Amministrazione" is Italian for "Administration") was an example of how cybercriminals can use social engineering to trick unsuspecting users into infecting their computers.

hlp-admin.jpg

If opened, the help file displays an error message:

hlp-error.jpg

In the background, however, a file called Windows Security Center.exe is being dropped onto the computer, which in turn creates a file called RECYCLER.DLL.

hlp-dropped.jpg

Read more: http://nakedsecurity.sophos.com/2012/09/10/keylogger-help-file/
 

Gnosis

Level 5
Apr 26, 2011
2,779
Windows XP "help" is a joke, so I removed it long ago when something came along called "GOOGLE". LOL
I have found that Microsoft likes to dance around, or put you on a rabbit trail, when asked a straightforward question
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top